[Server-devel] [Techteam] signing leases.sig [Fwd: new package: xs-activation]

C. Scott Ananian cscott at laptop.org
Tue Sep 2 13:29:05 EDT 2008


On Tue, Sep 2, 2008 at 1:44 AM, Douglas Bagnall <douglas at paradise.net.nz> wrote:
> To DOS all the laptops in a school, you can give the XS a lease.sig
> containing syntactically correct but otherwise bad data.  The attack
> would manifest itself over time, as each XO came to update its lease.

The bitfrost.leases.crypto module contains routines to verify a given
activation lease or developer key; the intention was that the school
server never replace a valid key with an invalid or shorter key.
   http://dev.laptop.org/git/projects/leases
packaged in the 'olpc-update' RPM.  API docs:
  http://dev.laptop.org/~cscott/joyride-api/bitfrost.leases.crypto-module.html
 --scott

-- 
 ( http://cscott.net/ )


More information about the Server-devel mailing list